CVE-2016-3709: XSS
Published Jul 28, 2022
·Updated
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
Affected Software
2 affected componentsFixes available
redhat/libxml2<2.9.11
2.9.11
XMLSoft Libxml2>=2.9.2<2.9.11
Event History
Jul 28, 2022
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 1, 2022
Data Sourced
via Red Hat·05:31 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2016-3709?
CVE-2016-3709 refers to a possible cross-site scripting vulnerability in libxml after commit 960f0e2.
2
What is the severity of CVE-2016-3709?
The severity of CVE-2016-3709 is medium with a severity value of 6.1.
3
What software is affected by CVE-2016-3709?
The libxml2 package with version up to exclusive 2.9.11 and Xmlsoft Libxml2 with versions between inclusive 2.9.2 and exclusive 2.9.11 are affected by CVE-2016-3709.
4
How can I fix CVE-2016-3709?
To fix CVE-2016-3709, update the libxml2 package to version 2.9.11 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2016-3709?
The Common Weakness Enumeration (CWE) ID for CVE-2016-3709 is 79.